Physical Address
304 North Cardinal St.
Dorchester Center, MA 02124
Physical Address
304 North Cardinal St.
Dorchester Center, MA 02124


A “Compliance Policy” in Microsoft Intune is used to define rules and conditions that managed devices must respect in order to be considered compliant. These policies help to secure the organization’s data and resources by ensuring that only compliant devices can access these resources.
Here are some key points about “Compliance Policies” in Intune :
In this article, I’m going to show you how to create a compliance policy in Intune, Microsoft’s Mobile Device Management (MDM) solution and to link non compliant devices notification with your system ticket.



In device health section, I’ll require BitLocker, Secure Boot and Code Integrity.

In system security section, I’ll require this password complexity settings

Also Requiring :

On the Actions for noncompliance tab, specify a sequence of actions to apply automatically to devices that don’t meet this compliance policy.
Mark device noncompliant is selected by default, but we will comeback later to add another action here.




Nowadays, almost all ticketing systems are configured with a mailbox, allowing you to open a ticket as soon as you receive a new e-mail.
In this article, we’ll configure Intune to send notifications of non-compliant devices to the ticketing system to open a ticket and correct these problems as soon as possible.
To do this :

Enter Name in the Basics tab then click “Next“


Here is an example of the message I’m using :
Hello {{UserName}}
Your computer {{DeviceName}} is not compliant with company security rules.
You can continue to use your computer but a technician will contact you shortly to correct the problem.
Thank you
Your IT Team

Here is Notification message templates added.




Before starting any configuration, you need to know that to perform this action, you need to have/create a Microsoft 365 group (you can do it from Exchange Online or from Azure) to group the addresses to be notified.
Once you’ve created the Microsoft 365 group and added the ticket system’s e-mail address to it, you need to authorize the reception of external e-mails (this little trick took me two days of research, why I don’t receive e-mails ? 🤣).
here is the steps to enable reciving external emails :

Now that we are done with Microsoft 365 group, we can come back to configuration :



In the second line :



As you can see here, I have GIT0100 as compliant device, I will disable firewall to make device non compliant. Let’s see what’ happen.

Here, I have disabled firewall.

We need to start manual sync to get result quickly.

As you can see ma device is no more compliant.

Intune will now send two notifications :
Here is new email recived in my Helpdesk mailbox as you can see, a new ticket will created automatically.

In summary, compliance policies in Microsoft Intune play a crucial role in securing corporate devices and data. By defining clear rules and monitoring device compliance, administrators can ensure that only secure, up-to-date devices access sensitive resources. Integration with conditional access further enhances this security, offering robust protection against potential threats. By adopting these policies, organizations can not only improve their security posture, but also simplify device management and reduce the risks associated with non-compliance.